A Business Associate Agreement is not a terms-of-service checkbox. It is how you document that a vendor accepted HIPAA duties for PHI they handle on your behalf. Email hosts, cloud fax providers, and online form tools all land in that category when patient data is in the payload.
Ask before you send the first message
- Will they sign a BAA before production use, not after a breach?
- Who is responsible for breach notification timelines?
- Where is data stored, and who are their subcontractors?
- Can you export or delete records if you leave?
Why one agreement is easier than three
Many clinics collect a BAA for email, forget the fax vendor, and never ask the form builder. That gap is what investigators notice. HIPAA Companion includes a BAA on every plan and covers healthcare email, secure fax, and personalized forms in the same relationship so the paperwork matches the workflow.
Keep signed copies with your other vendor files. Review them when you add a location or a new message type, not only when someone asks for a binder.
